
Sefas Innovation Inc, a customer communication management software company and vendor for Frost Bank and Monson Savings Bank, disclosed a data breach that exposed the personal and financial information of customers.
Sefas Innovation provides document composition software, software development services and software support to the banks using a secure file transfer protocol (SFTP) server.
On or about April 16, 2026, Sefas learned that an unauthorized group claimed possession of data associated with both of the organizations it supports. The company began an investigation and engaged cybersecurity specialists to determine the nature and scope of the incident.
The investigation revealed activity consistent with unauthorized access to the SFTP server used to provide software support. This unauthorized activity included the download of certain files intermittently between December 2025 and April 2026.
Sefas informed Frost Bank about the incident on April 22, 2026, and began providing information so that affected individuals and the specific data involved could be identified.
For Frost Bank customers, the types of personal information exposed included names, addresses, Social Security numbers or other taxpayer identification numbers, account numbers, dates of birth and loan numbers.
At this time, for Monson Savings Bank customers, the types of personal information exposed have not been publicly disclosed.
Based on the evidence reviewed, the company stated there was no indication that the unauthorized activity extended beyond the SFTP server or continued after April 16, 2026.
The company began sending notification letters to affected Frost Bank customer on May 20, 2026, and to affected Monson Savings Bank customers on July 9, 2026.
Sefas is providing affected individuals with 12 months of credit monitoring, credit report and credit score services at no charge through Cyberscout. The company is also providing proactive fraud assistance to help with questions or in the event that an affected individual becomes a victim of fraud.
To enroll in credit monitoring, affected individuals can visit the Cyberscout activation page and enter the unique code included in their notification letter. Enrollment must be completed within 90 days of the date of the letter.
Affected individuals with questions can call 1-844-593-8461 or 1-833-851-9638, Monday through Friday from 8:00 a.m. to 8:00 p.m. ET, excluding major U.S. holidays. They may also write to the company at 20 Burlington Mall Road, Suite 210, Burlington, MA 01803 or call 781-757-3011.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)